Learn to leverage Windows diagnostics for detecting system compromises in this 35-minute conference talk from Derbycon 2015. Explore a novel technique that complements existing methods like VBA macros. Discover the potential of PowerShell 2.0 in RMM and Microsoft Code Signing. Gain insights into Windows Diagnostics output and the TerraDoe tool. Understand how to disable TerraDoe and explore future developments in this field. Acquire valuable references for further study on system compromise detection techniques.
Overview
Syllabus
Introduction
What is this about
Why should you be here
This is a new technique
Not a perfect replacement
Current state of the art VBA macros
Whats another diagnostic tool
PowerShell 20 in RM
Microsoft Code Signing
PowerShell
Windows Diagnostics
Output
TerraDoe
Disable TerraDoe
Whats next
References
Thank you